First-ever AI malware ‘LameHug’ hides in ZIP files to hack Windows PCs

A new malware named LameHug is using Alibaba's large language models (LLM), the very same tech that powers AI chatbots like ChatGPT, to generate and run commands and steal information from Windows machines.

LameHug malware is using Qwen-2.5-Coder-32B-Instruct, an open-sourced large language model developed by Alibaba to generate and run commands.LameHug malware is using Qwen-2.5-Coder-32B-Instruct, an open-sourced large language model developed by Alibaba to generate and run commands. (Image Credit: AI/Microsoft Designer)
2 min readNew DelhiJul 20, 2025 08:53 AM IST First published on: Jul 19, 2025 at 01:59 PM IST

A new family of malware called LameHug is infecting systems around the world using the very same tech that powers AI chatbots like ChatGPT, Gemini, Perplexity and Claude. Discovered by the Ukrainian national cyber incident response team (CERT-UA), the malware uses large language models to generate and run commands to infect and steal information from Windows PCs.

CERT-UA says that the attacks are from the Russian threat group APT028. Written in the popular coding language Python, LameHug uses APIs from Hugging Face and is powered by Qwen-2.5-Coder-32B-Instruct, an open-sourced large language model developed by Alibaba Cloud to generate and send commands.

Latest Comment
Post Comment
Read Comments